theme

Nexter Vulnerabilities

2 known security issues reported for the Nexter WordPress theme. Most recent disclosed Oct 12, 2023.

1 high 1 medium

Running Nexter on your site? Check whether your installed version is affected.

Scan your site free

Nexter <= 2.0.3 - Authenticated (Subscriber+) SQL Injection via 'to' and 'from'

high

The Nexter theme for WordPress is vulnerable to SQL Injection via the 'to' and 'from' parameters in versions up to, and including, 2.0.3 due to insufficient escaping on the user supplied parameter and lack of valid preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscri...

CVSS:
8.8
Affected:
up to 2.0.3
Fixed in:
2.0.4
Disclosed:
Oct 12, 2023

CVE-2023-45657 on NVD →

Nexter <= 2.0.3 - Missing Authorization

medium

The Nexter theme for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on several functions such as nexter_extra_ext_active_ajax, nexter_extra_ext_deactivate_ajax, nexter_ext_wp_replace_url_settings_ajax, nexter_ext_wp_duplicate_post_settings_ajax, nexter_ext_save_data_ajax,...

CVSS:
4.3
Affected:
up to 2.0.3
Fixed in:
2.0.4
Disclosed:
Oct 12, 2023

CVE-2023-45658 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database